Law / Malawi

Malawi

4 of 8 named instruments researched to a stage, across three of the six areas of law we track: 3 in force and 1 enacted but not yet in force. As of 5 September 2026.

  1. AI law none researched
  2. Privacy law 2
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (211 words)

Malawi's general personal-data regime is Part VII of the Electronic Transactions and Cyber Security Act, 2016, in force since 1 June 2017, which binds a data controller, any person who determines the purpose and manner of processing, to process personal data fairly and lawfully, collect it only for specified and legitimate purposes, keep it no longer than necessary, and process it only on a lawful basis such as the data subject's unambiguous consent, contractual necessity, or a legal obligation.

The Act also gives a data subject notice, access, and rectification or erasure rights, and requires a data controller to implement technical and organizational security measures; it sets no cross-border-transfer rule and no dedicated breach-notification duty, and states no penalty specific to a Part VII breach, so the Act's general default offence (a fine of K5,000,000 and imprisonment for seven years) applies.

Malawi separately enacted the Data Protection Act, 2024, which the Malawi Communications Regulatory Authority (MACRA) administers as the Data Protection Authority and describes as regulating, monitoring and enforcing compliance around how personal data is collected, processed, stored, and shared across sectors, covering both public and private organisations; its text is published only as a scanned image, so its lawful-basis, automated-decision, sensitive-data, cross-border-transfer, breach-notification, and penalty provisions are not described here.

Comprehensive regime

Data Protection Act, 2024

Data Protection Act, 2024Malawi Communications Regulatory Authority (MACRA), file listing for the Act, and MACRA's own account of the Act on its website

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 9, 2025. Publisher's page: https://macra.mw/2025/06/24/macra-engages-mdas-in-data-protection/

Commencement not set. Binds public and private bodies.

What this law does

The Malawi Communications Regulatory Authority (MACRA) describes the Act as positioning MACRA itself as the Data Protection Authority, charged with regulating, monitoring, and enforcing compliance around how personal data is collected, processed, stored, and shared across sectors, and as promoting responsible management of personal data by both public and private organisations.

The Act's own text was not obtained: the copy hosted by MACRA is an image-only scanned PDF with no extractable text, and no other located copy, official or otherwise, could be read either. Its lawful-basis, sensitive-category, automated-decision, cross-border-transfer, breach-notification, and penalty provisions are accordingly not described here.

What it requires

Electronic Transactions and Cyber Security Act, 2016, data protection and privacy (Part VII)

Electronic Transactions and Cyber Security Act, 2016, Part VII (ss. 71-74)official consolidated Act text, Malawi Legal Information Institute (MalawiLII)

In force since 1 June 2017. Binds public and private bodies.

What this law does

Section 71 requires a data controller to ensure personal data is processed fairly and legally, collected for specified, explicit and legitimate purposes and not further processed incompatibly with those purposes, kept adequate, relevant and not excessive, accurate and up to date, and kept in identifiable form no longer than necessary; personal data may be processed only where the data subject has unambiguously consented, where processing is necessary for a contract with the data subject, for compliance with a legal obligation, or on other grounds the section lists.

Section 72 entitles a data subject to obtain from a data controller, without constraint or unreasonable delay and at no expense, confirmation of whether data about him is being processed, communication of the data undergoing processing, and the rectification, erasure or blocking of data whose processing does not comply with the Act.

Section 73 requires a data controller, when collecting data from a data subject, to give him the identity of the controller, the purpose of the processing, and the existence of the rights of access, rectification and objection.

Section 74 requires a data controller to implement technical and organizational measures to protect personal data against accidental or unlawful destruction or loss, alteration, unauthorized disclosure or access, and other unlawful processing, at a level appropriate to the risks.

Part VII states no penalty of its own; a breach falls to the Act's general default offence at section 95, a fine of K5,000,000 and imprisonment for seven years for a violation of any provision whose penalty is not otherwise stated. Part VII does not address transfer of personal data outside Malawi and sets no distinct breach-notification duty to a regulator or to the data subject.

What it requires

Scraping law1 instrument, 1 in force

Research summary (305 words)

Malawi has no scraping-specific statute, so general law governs each dimension separately.

The Electronic Transactions and Cyber Security Act, 2016 prohibits a person from gaining unauthorized access to, intercepting, or interfering with data, and separately makes it an offence to intentionally access or intercept data without authority or permission, or to exceed authorized access; unlike some neighbouring jurisdictions' computer-misuse laws, the offence does not require that the person defeat a security measure to gain access, so whether reading a public, unauthenticated page without logging in or accepting terms falls within accessing data 'without authority or permission' is unsettled, and no reported Malawian case has tested the point.

No Malawian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act, 2016 permits quotations from a lawfully published work, including newspaper press summaries, and reproduction for reporting current events, both subject to a fair-practice and extent-justified test, and separately permits critical or scientific use and personal or private single-copy use, but it has no text-and-data-mining exception, so training a model on scraped copyrighted text does not obviously fit any of the Act's permitted-use categories.

The Act protects a 'compilation of data' as an intellectual creation by reason of its selection or arrangement, but its own definition states that this protection does not extend to the data itself, so Malawi confers no sui generis database right beyond ordinary compilation copyright.

The Electronic Transactions and Cyber Security Act's personal-data provisions apply to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Malawian website remains subject to the Act's fair-processing, purpose-limitation and lawful-basis duties.

No Malawian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Electronic Transactions and Cyber Security Act, 2016, unauthorized access to data

Electronic Transactions and Cyber Security Act, 2016, s. 84 (unauthorized access, interception or interference with data)official consolidated Act text, Malawi Legal Information Institute (MalawiLII)

In force since 1 June 2017. Binds public and private bodies.

What this law does

Section 84(1) prohibits a person from gaining unauthorized access to, or intercepting, or interfering with data. Section 84(3) makes it an offence for a person to intentionally access or intercept any data without authority or permission to do so, or to exceed authorized access, punishable on conviction by a fine of K2,000,000 and imprisonment for five years; unlike Kenya's neighbouring provision, the offence does not require defeating a security measure to gain access.

Section 84(10) raises the penalty to imprisonment of not less than ten and not more than fifteen years, with no separate fine stated, where the data concerned is data connected with national security or the provision of an essential service. Because the offence turns on accessing data without authority rather than on circumventing a technical control, its reach to a scraper reading a public, unauthenticated page is unsettled.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (297 words)

Malawi has no Digital Single Market-style press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

The relevant instrument is the Copyright Act, 2016, which repealed the earlier Copyright Act, and whose section 39 permits, without the copyright owner's consent, the inclusion of quotations from a lawfully published work in another work, including quotations from newspaper articles and periodicals in the form of press summaries, subject to a fair-practice and extent-justified test.

Section 45 separately permits reproducing and making available to the public a work that can be seen or heard in the course of a current event, for the purpose of reporting on that event, to the extent justified for an informative purpose.

Neither provision is capped at a headline-length or short-extract threshold beyond the fair-practice test, and no reported Malawian decision applies either to a systematic news aggregator, as opposed to a traditional press summary or a broadcaster's current-events report.

Section 82 gives a publisher a right against facsimile reproduction of the typographical arrangement of a published edition, lasting twenty-five years from the end of the year the edition was first published, but this protects the printed page layout against photocopying, not the underlying text or headlines, so it does not reach a news aggregator's reproduction of content the way a Digital Single Market Article 15-style neighbouring right would.

The Act defines a 'compilation of data' as protected by reason of its selection or arrangement, but expressly states that this protection does not extend to the data itself, so the Act predates and has no equivalent of a machine-readable text-and-data-mining reservation.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.